AI Act · companies that use AI

AI Act for companies that use AI

Most AI Act obligations fall on those who build AI. A company that only uses AI (the deployer) still has obligations of its own — and some already apply. Here is an overview by date and the tools that help you find your way.

What applies and from when

  1. 2 Feb 2025

    AI literacy and prohibited practices

    Companies take measures to support the AI literacy of the people operating and using AI systems on their behalf. Regulation (EU) 2026/1744 reworded the duty: no specific level of literacy of any individual has to be guaranteed. Prohibited practices must not be used — the one closest to an ordinary company is inferring employees' emotions in the workplace, unless for medical or safety reasons.

    Art. 4(1) of Regulation (EU) 2024/1689 · Art. 5(1)(f) of Regulation (EU) 2024/1689 · Art. 113(3)(a) of Regulation (EU) 2024/1689

  2. 2 Aug 2026

    Transparency

    A deployer of emotion recognition or biometric categorisation informs the persons exposed. Deep fakes and text published to inform the public on matters of public interest are disclosed as artificially generated (not required for text that underwent editorial review with editorial responsibility). Telling people they are talking to an AI chatbot is the provider's duty — check it with your vendor.

    Art. 50(1) of Regulation (EU) 2024/1689 · Art. 50(3) of Regulation (EU) 2024/1689 · Art. 50(4) of Regulation (EU) 2024/1689 · Art. 113(2) of Regulation (EU) 2024/1689

  3. 2 Dec 2026

    New prohibitions and output marking

    The prohibitions added by Regulation (EU) 2026/1744 apply: intimate imagery of an identifiable person without their explicit consent and child sexual abuse material. Providers of generative systems placed on the market before 2 Aug 2026 must mark outputs in a machine-readable format by this date.

    Art. 5(1)(ba) of Regulation (EU) 2024/1689 · Art. 5(1)(bb) of Regulation (EU) 2024/1689 · Art. 111(4) of Regulation (EU) 2024/1689

  4. 2 Dec 2027

    High-risk systems (Annex III)

    If you use AI for example in recruitment or to assess the creditworthiness of natural persons, the deployer obligations apply from this date: use the system per its instructions, human oversight, monitoring and log retention. The date was set by Regulation (EU) 2026/1744.

    Art. 6(2) of Regulation (EU) 2024/1689 · Art. 26(1) of Regulation (EU) 2024/1689 · Art. 113(3)(c) of Regulation (EU) 2024/1689

How NISMap helps

Tools that exist in NISMap today. Results are indicative, not legal advice.

Slovak and Czech AI Act laws

The Regulation applies directly. The laws designating supervisory authorities and penalties have not yet been adopted in Slovakia or the Czech Republic — the drafts are in the legislative process. NISMap therefore cites no national provision. We follow the developments in the regulatory feed.

Regulatory feed

Classification in an AI assistant (MCP)

The public NISMap MCP server offers the same classification as the ai_act_classify tool. An assistant that supports MCP passes the system's properties and gets the category, obligations with citations and dates of application. No signup and no API key.

claude mcp add --transport http nismap https://nismap.com/api/mcp
MCP server documentation

Frequently asked questions

Does the AI Act apply to a company that only uses AI?

Yes. Whoever uses an AI system under its authority (outside personal non-professional activity) is a deployer under Art. 3 of Regulation (EU) 2024/1689. It has obligations of its own: literacy under Art. 4(1) of Regulation (EU) 2024/1689, prohibitions under Art. 5(1) of Regulation (EU) 2024/1689, transparency under Art. 50(3) of Regulation (EU) 2024/1689 and Art. 50(4) of Regulation (EU) 2024/1689, and for high-risk systems the obligations under Art. 26(1) of Regulation (EU) 2024/1689 and the following paragraphs.

Do employees need an AI literacy certificate?

No. Art. 4(1) of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 requires measures supporting literacy, taking into account people's knowledge, the context of use and the persons affected. No specific level of literacy of any individual has to be guaranteed.

We have a chatbot on our website. What do we have to do?

Under Art. 50(1) of Regulation (EU) 2024/1689 the provider must design the chatbot so that people know they are interacting with an AI system (unless obvious). Check it with your vendor; if you build the chatbot yourself, the duty is yours. It applies from 2 Aug 2026.

When do the obligations for high-risk systems apply?

For Annex III systems from 2 Dec 2027 under Art. 113(3)(c) of Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. An Annex III system is not high-risk if it meets one of the conditions of Art. 6(3) of Regulation (EU) 2024/1689 — except where it profiles natural persons, which is always high-risk.

Find out which obligations apply to you

Record your AI systems in the inventory and get an indicative classification with citations and dates for each.

Start an AI system inventory

Indicative overview under Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, not legal advice. Slovak and Czech national AI Act laws are not taken into account. For a binding assessment, consult a legal adviser.